Wednesday, 7 November 2012

Don't give away free porn


As if you need more reasons to be careful or (better yet) anonymous online, this past week, an illegal file sharer was fined $1.5 million for distributing movies through BitTorrent.

So here are the details: The defendant, Kywan Fisher, was sued earlier this year by adult entertainment company Flava Works after being caught sharing 10 of their films on torrent sites. Fisher had actually purchased the films originally, but decided to spread the love online.

Unfortunately for Fisher, Illinois federal court Judge John Lee wanted none of his love and ordered Fisher to shell out $150,000 per movie.

“Defendant's conduct was willful to the extent that he copied or distributed Flava Works, Inc.' intellectual property at least 10 times and caused the videos to be infringed or downloaded at least 3,449 times,” Lee wrote in a legal memo.

You’re probably thinking this is a pretty harsh punishment for sharing a few tasteful films. This guy must have had the worst representation. Well, as it turns out, he had no representation. He never showed up for court.

Look, we aren’t going to tell you what you should or should not do online. In fact, at SumRando, we have no idea what you do online. But should you choose to break the law, at least be careful about it. You know who wasn’t using a VPN like SumRando? Kywan “I owe $1.5 million” Fisher, that’s who.

And should you get caught, for goodness sake, show up in court!

Friday, 2 November 2012

Wednesday, 31 October 2012

Istanbul node launching this Friday!


Hey everybody,

Exciting news!

If you haven’t been watching our Facebook or Google+ pages, you’ll be excited to hear we will officially be launching our newest server this Friday in Istanbul!


The new node will provide epically high-speed connections to all our friends in the Mediterranean and Middle East and give randos everywhere a new connection option.

Look, we know picking the right VPN can be difficult — we’ve been there too. There are all kinds of things to consider.  At SumRando, we think of our users as an anonymous community. Some of you are techies, others are doing important work tasks, and still others are casual coffee shop surfers who simply want to keep their data safe and anonymous.

Whichever category you fall into, we are there for you.

Some of our competitors like to brag about huge numbers of servers and thousands of IP addresses. That’s fine if you’re ok with connection speeds on par with dial-up. But at SumRando, we think a VPN should enhance your web experience, not hold it back. That’s why, unlike other VPNs, we own all of our servers (that’s right, hardware and all) and can promise blindingly quick connections around the world.

Our new Istanbul node will increase the scope, speed, and accessibility of our VPN; all while continuing to provide you with the same friendly customer service and support you’re used to.

So get exited for the launch of our new node in Istanbul and feel free to drop us a line or send us some feed back to tell us what you think!

Friday, 26 October 2012

Google, Yahoo, and Microsoft busted using weak cryptographic keys.

Trust nobody.

Ok, you can trust us. But really, sometimes it feels like even the best security just isn't enough. And sometimes, even the most trusted companies cut corners.

On Wednesday, a mathematician named Zachary Harris found that Google, Yahoo and Microsoft were using shoddy security measures in their email clients. As it turns out, all three companies were using keys less than 1,024 bits in length in their DomainKeys Identified Mail (DKIM) mechanism (Google was using a 512 bit key).

DKIM keys are used by domains as certificates to verify to mail recipients that the mail is indeed from who it claims to be. Think of it as a really complicated digital signature. Were someone to crack the key, they could easily impersonate anyone from the domain. In this case, the hacker could impersonate anyone at Google.

Harris discovered the security flaw last December when he received an email from a Google headhunter. 
Harris was intrigued, but skeptical. The e-mail had come to him last December completely out of the blue, and as a mathematician, he didn’t seem the likeliest candidate for the job Google was pitching. 
So he wondered if the e-mail might have been spoofed – something sent from a scammer to appear to come from the search giant. But when Harris examined the e-mail’s header information, it all seemed legitimate. [Wired] 
But then Harris saw Google was using week cryptographic key to sign their emails -- only 512 bit.
Harris thought there was no way Google would be so careless, so he concluded it must be a sly recruiting test to see if job applicants would spot the vulnerability. Perhaps the recruiter was in on the game; or perhaps it was set up by Google’s tech team behind the scenes, with recruiters as unwitting accomplices.
Google never got back to Harris, but two days after he contacted them, the cryptographic keys were switched to 2,048 bit. Yahoo and Microsoft have followed suit.

Harris also reported that other companies including Ebay, Twitter, Paypal and HSBC are using weak keys.

Wednesday, 24 October 2012

8% of Android apps are vulnerable to attack


How often do you use apps on your mobile device? If you’re like us, you probably connect to the web via mobile apps dozens of times per day. And, hopefully, like us, you realize that mobile devices are no safer than personal computers when it comes to sending sensitive material over the web. Unfortunately, most people don’t share this sense of caution and operate under the false confidence that mobile devices are hack-proof or somehow more secure than a PC.

But in efforts to test this sense of security, security researchers at the Leibniz University of Hanover in Germany conducted a study looking at ways popular Android apps in the Google Play marketplace handle attacks on security protocols called Secure Sockets Layer (SSL) and Transport Layer Security (TLS).

Most browsers will show a lock image when connecting
via SSL or TLS indicating the connection is secure.
Horrifyingly, the study found that about 8% of the apps examined misused these two security protocols, leaving users’ sensitive information vulnerable to exposure. And we’re talking really sensitive data – think credit card numbers and passwords.

Fortunately, the researchers said they have no evidence these attack strategies are currently being used.

SSL and TLS work by encrypting data over network connections to, theoretically, keep user information safe from extraction. The protocols are used extensively all over the web and especially by Android applications to transmit things like credit card credentials and other sensitive data.

Researchers used a tool called MalloDroid to execute “Man in the Middle” (MITM) attacks on the selected apps. In a MITM attack, the hacker places himself in the middle of a SSL or TLS connection and monitors activity as the app communicates with its target.

We introduce MalloDroid, a tool to detect potential vulnerability against MITM attacks. Our analysis revealed that 1,074 (8.0%) of the apps examined contain SSL/TLS code that is potentially vulnerable to MITM attacks. Various forms of SSL/TLS misuse were discovered during a further manual audit of 100 selected apps that allowed us to successfully launch MITM attacks against 41 apps and gather a large variety of sensitive data. Furthermore, an online survey was conducted to evaluate users' perceptions of certificate warnings and HTTPS visual security indicators in Android's browser, showing that half of the 754 participating users were not able to correctly judge whether their browser session was protected by SSL/TLS or not. [LUH]

More than any time before, we, as consumers, rely on tech providers to protect our sensitive data. But the fact is, no company provides flawless security. At SumRando, we encourage all of our users to not only educate themselves on security issues, but to take responsibility for their online safety with a solid VPN.